Some Telus subscribers are being told that intruders sat inside their accounts for over a year using stolen passwords; Telus is one of Canada’s biggest telecom carriers.
Notices sent to affected consumer telecom subscribers put the intrusion window at February 2025 through June 2026. The attackers reached names, account and phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history.
Telus said the lifted data has been used to try to talk customers into moving their services to competitors, and that some victims had their accounts altered without permission. No account count has been disclosed.
Compromised credentials have been reset and monitoring layered onto the affected accounts, Telus said. The carrier also alerted the Vancouver Police Department and extended identity theft protection to victims.
The sparse description points to credential stuffing or another account-takeover campaign fed by passwords pulled from a third party, though Telus has not said the abused passwords came from outside its own systems.
The disclosure adds to a bruising stretch for the carrier. March brought a separate admission from subsidiary Telus Digital, after the ShinyHunters crime group said it had taken about a petabyte of data.
For subscribers, the practical steps are unchanged: rotate passwords, turn on a second factor, and treat cold calls about a phone or internet plan as suspect.
